Skip to content
RRepoOps
DocsPricing
Sign inStart building ↗Dashboard
Trust & policies

Privacy Policy

RepoOps Privacy Policy. What we collect, what we never see, where it lives, and your GDPR rights.

Last updated: 2026-10-05

The short version

  • The desktop app runs on your machine. We never see your code or your agent prompts, and we never see your brain files unless you switch on a feature that sends them (publishing a brain page, or brain sync on the paid hosted tiers).
  • One thing does leave by default: an anonymous reliability beacon (crash and version counts, no code, no prompts, no file names). You can turn it off in the app.
  • Brain Dreaming and Ask synth call your model provider using your own API key. On the desktop app the call goes straight from your machine and never touches our servers. On the hosted tiers it is made by our server, but on your key, to your chosen provider (Anthropic, OpenAI or OpenRouter): we pass the request through and write neither the prompt nor the answer to our database. Your question and the answer are held in server memory, keyed to your account, for up to 30 minutes, so asking the same thing again does not cost a second model call. Hosted Ask will not run at all until you supply a key.
  • If you sign in to repoops.ai we store the minimum needed to bill you and run a hosted team (name, email, organization, billing identifiers, hashed device IDs).
  • You can export or delete your hosted-account data at any time via /account/export and /account/delete.

1. What we collect

1.1 Desktop app (local only)

The desktop app reads files under repos you add and writes a local SQLite database in your data directory. It also reads the session stores that coding agents keep on this machine, including Claude Code, Cursor, Codex, Copilot, Continue, Cline, Roo, Aider, Windsurf, Xcode and Claude Desktop; several of those stores live in your home directory rather than inside a repo, so records of work outside the repos you added can appear. Your code never leaves your machine, and neither do your brain files or your prompts until you switch on a feature that sends them.

One thing does leave, and it is on by default: an anonymous reliability beacon. When the server crashes, wedges, hits a memory ceiling, or recovers, the app sends one event to PostHog (a sub-processor) so we can find and fix the failure. The event carries a reason code, the app version, your platform and architecture, memory use, uptime, and a random per-install ID. It carries no code, no file names, no repo names, and nothing that identifies you. The app tells you this on first run. Turn it off from the tray menu, or set REPOOPS_HEALTH_BEACON=0 to disable it and the install-to-activation events outright. Nothing else leaves your machine unless you explicitly bind the install to a hosted team.

1.2 repoops.ai (hosted)

If you fill in the download form or the enterprise contact form, we store what you type (name, email, and for enterprise the company, team size and use case), plus the operating system you picked and your browser user agent. We send ourselves a notice the first time we see an email address. No account is created and no card is asked for.

If you sign in:

  • Account fields: name, email, organization name, OAuth provider IDs (Google/GitHub), authentication tokens, billing customer ID.
  • Personal brain content (opt-in, one source at a time): when you connect a source to My Brain (Gmail, Google Drive, Google Calendar, Notion, Slack, X, Readwise, web search, your agent sessions, or an uploaded chat export), we fetch that content and store it in our database so you can search and cite it: email bodies, documents, calendar events, messages. We strip secrets and personal identifiers server-side before writing each row, every imported record lands as a proposal you confirm or reject, we store the connected account’s access tokens encrypted, and disconnecting a source deletes everything it brought in.
  • Billing: Stripe customer ID, subscription IDs, plan, seat counts, invoice history. Card numbers stay with Stripe.
  • Team telemetry (Solo Hosted / Team tiers, opt-in): redacted Claude Code session metadata (model, tokens, cost, duration) - never prompts or completions.
  • Server-side errors: request URL, error message, stack trace. Sent to Sentry. No user identifier, no request body, no headers, no cookies.
  • Product analytics (opt-in via cookie banner): page views, button clicks, anonymous session IDs, and (when you accept) Sentry Session Replay - a masked recording of your own session for debugging, with text and inputs masked by default. Sent to PostHog, Google Analytics, Vercel Web Analytics, and Sentry. None of these load until you accept; “Reject all” keeps them all off.
  • Operational logs: Vercel access logs (IP, user agent, response code) retained 30 days for debugging and abuse response.

1.3 Cookies

We use three kinds of cookies. The first kind is set automatically; the third requires your consent via the cookie banner.

  • Strictly necessary (session cookie, CSRF token, billing return URL) - exempt from consent under GDPR / PECR.
  • Authentication (NextAuth session + refresh) - set after you sign in. Exempt from consent because you explicitly authenticated.
  • Product analytics (PostHog, Google Analytics, Vercel Web Analytics, Sentry Session Replay) - set only after you accept analytics via the cookie banner. One click rejects all.

2. What we never see

  • Your source code.
  • The contents of your .claude/brain/ files, unless you switch on a feature that sends them. Two do: publishing a brain page, and brain sync on the Solo Hosted and Team tiers, which copies the brain files you own to your hosted account. Both are off until you turn them on.
  • Your model prompts or completions. On the desktop app they never reach us. On the hosted tiers the request passes through our server on its way to the provider you chose, on your key, and is never written to our database. The one exception is stated rather than buried: the question and the synthesized answer sit in server memory, keyed to your account, for up to 30 minutes (see 3, Retention).
  • Your local Claude Code transcripts.

3. Retention

  • Free local desktop: no hosted account record. Anonymous reliability events go to PostHog by default and you can turn them off (see 1.1); nothing else leaves your machine unless you bind to a hosted tier.
  • Hosted Ask answer memo: a synthesized answer, and the question that produced it, are held in server memory for up to 30 minutes so a repeated question does not cost a second model call. Keyed to your account, never written to the database, and dropped whenever your brain changes. This is the same memo disclosed in section 3 of the Terms.
  • Solo Hosted / Team: usage and telemetry retained 30 days; cloud audit events retained 13 months; synced commit and pull request records retained 13 months; synced brain records (decisions and lessons) kept until you delete the account or your organization's retention rule removes them; account activity records (invites, role changes, device binds) kept for the life of the account; billing records 7 years (US tax requirement).
  • Enterprise: configurable per the DPA.
  • Deletion grace period: your name, email and avatar are scrubbed the moment you submit a delete request, and that part cannot be undone. The account row itself is removed 30 days later; email support@repoops.ai within those 30 days to halt that final removal.

4. Sub-processors

ProviderRoleRegion
NeonPostgres database hostingUS-East
VercelApplication + edge hosting; Web Analytics (opt-in via cookie banner)Global
StripePayments + subscription billingUS/EU
ResendTransactional emailUS
PostHogProduct analytics on the website (opt-in via cookie banner)US
PostHogAnonymous desktop reliability beacon (on by default, opt-out in the app)US
Google AnalyticsWeb analytics (opt-in via cookie banner)US
SentryServer-side error reporting; Session Replay (opt-in via cookie banner)US/EU
AnthropicClaude API - the customer's own key, the customer's own sub-processor, on every tierUS
OpenAIChat Completions API - the customer's own key, the customer's own sub-processor, if they choose itUS
OpenAIWhisper speech-to-text for hosted voice input - a RepoOps-held key, so OpenAI is our sub-processor for this path, not the customer'sUS
OpenRouterModel routing - the customer's own key, the customer's own sub-processor, if they choose itUS
Voyage AIText embeddings for the hosted personal brain, when the operator configures it - a RepoOps-held key, so Voyage is our sub-processor for this pathUS

See the Data Processing Agreement for contractual terms with each sub-processor.

5. Your rights (GDPR / UK GDPR)

  • Access & portability: /account/export returns a JSON dump within minutes.
  • Erasure: /account/delete scrubs your name, email and avatar straight away and signs you out everywhere. That step cannot be undone. The emptied account record is hard-deleted 30 days later, and support can halt that last step if you ask.
  • Rectification: edit your name + email at /account.
  • Objection / restriction: email support@repoops.ai.
  • Complaint: you can lodge a complaint with your local supervisory authority (e.g. ICO in the UK, CNIL in France).

6. International transfers

Our primary infrastructure is in the United States. For EU/UK customers, we rely on the Standard Contractual Clauses (SCCs) included in the DPA and on each sub-processor’s own SCC commitments.

7. Children

RepoOps is not directed at children under 16. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided personal data, email support@repoops.ai and we’ll delete it.

8. Changes

Material changes will be posted here with at least 14 days’ notice to account holders by email.


See also: Terms of Service · Data Processing Agreement · Refund & cancellation policy.

Trust centerPrivacyTermsData processingSubprocessorsSecurity & disclosureContact
RepoOps

Understand the change.
Verify the fix.

Evidence for the investigation.
Reviewed remedies for what comes next.

Explore RepoOps

AttributionAI SecurityRemediationLLM Cost MetricsMemory

Learn and investigate

Sample investigationDocumentationCapture coverage

Start with confidence

Install RepoOpsPlans and pricingTrust and data handlingService statusContact
RepoOps / Investigate AI-assisted software changes.
PrivacyTermsSecurity
More resources and policies
RefundsSub-processorsCookiesData processingAboutTalk to salesChangelogBlog

© 2026 PromptReports LLC